Alert Type

PSN - Product Support Notification
Low/NotificationSoftware Release Notification
Low/NotificationSoftware Release Notification

Product Affected

ACX, EX, MX, PTX, QFX, NFX, SRX, VRR, vMX, vSRX Platforms.

Alert Description


Junos Software Service Release version 19.4R3-S9 is now available for download from the Junos software download site

Download Junos Software Service Release:

  1. Go to Junos Platforms - Download Software page
  2. Input your product in the "Find a Product" search box
  3. From the Type/OS drop-down menu, select Junos SR
  4. From the Version drop-down menu, select your version
  5. Click the Software tab
  6. Select the Install Package as need and follow the prompts

Solution

Junos Software service Release version 19.4R3-S9 is now available.

19.4R3-S9 - List of Fixed issues

PR NumberSynopsisCategory: Mojito PFE
1653216IRACL filters more than 64 might not work on IRB units
Product-Group=junos
On EX4300 series platform, limitation in IRACL (Ingress Routed Access Class list) filters applied to IRB units till 64, and filter applied beyond 64 will not work.
1671304Commit fails on EX4300 as EX4600 and EX4300 mixed virtual-chassis is not able to create more than 1024 IFLs
Product-Group=junos
Commit check fails on EX4300 when mixed mode virtual-chassis is configured between EX4600 and EX4300 and IFL (logical interface) is created on an aggregate interface having more than 1024 IFLs. Commit failure will be seen.
PR NumberSynopsisCategory: Mojito Platform
1655530The dc-pfe might crash due to the VCCP flap
Product-Group=junos
On all Junos EX and QFX platforms configured with Virtual Chassis (VC), with the Virtual Chassis Control Protocol (VCCP) flaps or any configuration change which causes VCCP to flap, might lead to the process dc-pfe crash.
PR NumberSynopsisCategory: Bug category for Mojito Royale routing implementation
1655654Few EX platforms does not generate ICMPv6 too big messages
Product-Group=junos
Few EX platforms may not generate ICMPv6 too long messages which could cause the path MTU (maximum transmission unit) discovery to fail. As a result, IPv6 session establishment may fail.
PR NumberSynopsisCategory: Category for all the Sazerac & Macallan PFE PRs
1653260L2PT may not work for AE interfaces in Q-in-Q environment.
Product-Group=junos
This issue Affects all EX-2300,EX-3400,EX-4300MP,EX4600,EX4600-40F. L2PT may not work for AE interfaces in Q-in-Q environment.
PR NumberSynopsisCategory: Category for all the Sazerac & Macallan platform related PRs
1649338The VC port might not be formed automatically after Zeroize
Product-Group=junos
On all EX3400/EX4400 platforms, the Virtual-Chassis (VC) port might not be formed automatically after executing the command "request system zeroize".
PR NumberSynopsisCategory: VC Infrastructure
1650967Virtual chassis instability when members are rebooted
Product-Group=junos
On EX4600, virtual chassis (VC) might unstable when members are rebooted.
PR NumberSynopsisCategory: DCBX
1599365File permissions are changed for /var/db/scripts files after reboot
Product-Group=junosvae
On QFX10K switches, file permissions are changed for /var/db/scripts files after reboot. This can impact scripts running on the box.
PR NumberSynopsisCategory: All issues related to QFX PFE CoS
1650051The fixed classifier may not work in MPLS and VXLAN scenario
Product-Group=junos
On QFX5100 platforms, traffic may not get classified based on a fixed classifier in MPLS as well as the VXLAN scenario.
PR NumberSynopsisCategory: PRs for Sflow on QFX 5100,5200, 5110
1598239Sflow impacts on ICMP traffic on QFX5XXX platforms
Product-Group=junos
On QFX5XXX platforms in sflow scenario, CPU/host bound ICMP traffic from or to the sampled interface might be dropped, which might have impact on services based on ICMP probes like RPM.
PR NumberSynopsisCategory: This is for Hw & Sw issues which are special for SPC3 car
1641793Traffic might be dropped due to the RX queue being full
Product-Group=junos
Incoming packets might be sent to RX queues of core0 or core14 mistakenly, might result in the queue buffer full and the packets getting dropped.
PR NumberSynopsisCategory: Border Gateway Protocol
1655228An RPD process crash may be observed, when the received prefix count exceeds configured "prefix-limit"
Product-Group=junos
In all Junos and Junos Evolved platforms, when the BGP neighbor is brought down due to the received prefix count exceeding configured "prefix-limit" and if BGP disable and enable operation performed to bring the BGP session up then the "rpd" process crash might be observed.
1669930BGP inactive routes may not be advertised to peers in BGP-LU scenario
Product-Group=junos
If BGP-LU(labeled-unicast) is configured using "rib inet.3/inet6.3" address family, BGP inactive routes are not re-distributed to BGP-LU peers, leading to improper traffic patterns.
PR NumberSynopsisCategory: Track PRs in BGP BMP area & is part of BGP inside RPD.
1477212The system might be unresponsive due to out of memory issue when BMP rib-out monitoring is enabled for large-scale BGP peers
Product-Group=junos
If BGP Monitoring Protocol (BMP) rib-out monitoring is enabled for large-scale BGP peers (such as 600+ peers) and there are large-scale routes (such as 2M routes) flapping, the system memory might be exhausted. This could cause the system to be unresponsive and RE rebooting etc.
PR NumberSynopsisCategory: QFX Control Plane VXLAN related
1524485The kernel crash might happen in EVPN-VXLAN scenario
Product-Group=junos
On all Junos platforms which support (Ethernet VPN) EVPN (Virtual Extensible LAN) VXLAN, if Aggregation Ethernet (AE) interface or Redundant Logical Tunnel (RLT) interface is configured in the underlay network for EVPN/VXLAN, when there is ARP request generated and flooded to the core side, the kernel crash might happen due to this issue.
PR NumberSynopsisCategory: Firewall Filter
1662955The MPC/FPC crash is seen on specific LC's running BGP Flowspec
Product-Group=junos
On Junos platforms with specific MPC/FPC model, crash may happen in certain scenario with BGP flowspec. With the BGP flowspec filter, the scaled prefix-list spread across the terms with a total prefix-list-scale. While processing the BGP flowspec filter with scale, it takes almost 6 minutes to consume the filter into ASIC during convergence. Since the PFE has a time max limit which is lesser than 6 scaled convergence time, PFE crash happens during the threshold handler. This causes the services or traffic impact running through the FPC until the FPC comes online and configurations are converged again.
PR NumberSynopsisCategory: Alias for DHCP issue on DNX based platform.
1607201ACX platforms running DHCP might not process packets arriving over IRB or MPLS
Product-Group=junos
ACX platforms running DHCPv4 will not process packets received from IRB interfaces or over MPLS core. Hence the DHCP reply packet from the server is not reaching the client.
PR NumberSynopsisCategory: Covers Application classification workflows apart from custo
1632205Signature package update may fail and the appid process may crash on SRX devices
Product-Group=junos
On SRX platforms, with a sig-pack update if any application is moved to DEPRICATED and if that application was part of any custom group, signature upgrade may fail. Due to this sometimes the appid process may crash.
1642383Flowd crash when back to back sigpack is updated at the time of stress traffic
Product-Group=junos
The flowd might crash when back to back sigpack is updated when heavy traffic is going on.
PR NumberSynopsisCategory: SNMP, mib2d issues
1669510The snmpd core might be observed with filter-duplicates configuration
Product-Group=junos
On all Junos and EVO platforms configured with filter-duplicates, the snmpd core might be observed if the SNMP query is made simultaneously from NMS (Network Management System) as well from the CLI.
PR NumberSynopsisCategory: SRX4100/SRX4200 Great Wall
1626562A major alarm DPDK (data plane development kit) Tx stuck issue of SRX4100/4200
Product-Group=junos
On the SRX4100 and SRX4200 platforms, it can detect DPDK (data plane development kit) Tx stuck issue and trigger a major chassis alarm goes which might trigger RG1 failover to the healthy node. A DPDK reset will be triggered only to the stuck port and if the reset resolves the tx stuck issue, the major chassis alarm will go off.
PR NumberSynopsisCategory: IDP policy
1657056The flowd core might be observed when IDP policy rulebase changes
Product-Group=junos
A change in IDP lsys policy configuration while the system is processing traffic may cause a flowd coredump in rare cases.
PR NumberSynopsisCategory: Inline Jflow PRs for defect & enhancement requests
1652901The syslog errors and PPE traps might be observed
Product-Group=junos
On MS-MPC/MPC-3D/MPC1/MPC1E/EX9200-40T/EX9200-40F/SRX5K-SPC-4-15-320/SRX5K-MPC/SRX5K-MPC3-100G10G/SRX5K-MPC3-40G10 linecards, syslog errors and PPE(Packet Forwarding Engine) traps might be observed due to exhaustion of NH partition of memory.
PR NumberSynopsisCategory: Atlas Integrated Routing & Bridging (IRB) module
1660208After changing the MTU on an aggregated interface along with IRB the kernel crash might be observed
Product-Group=junos
The kernel crash might be observed after changing the MTU on an aggregated interface along with integrated routing and bridging (IRB) on all Junos platforms.
PR NumberSynopsisCategory: High Availability/NSRP/VRRP
1651501A hardware issue is detected on the RG-0 primary node's CP
Product-Group=junos
On all SRX 5K products, when the chassis cluster is configured and there's a hardware issue with the CP (Central Point), failover might not happen correctly.
PR NumberSynopsisCategory: Firewall Network Address Translation
1645039Datapath daemon might crash resulting in total traffic and service failure
Product-Group=junos
On all SRX-Series devices, when policy configuration is modified and committed multiple times while the device is handling MS-RPC traffic with more than 1000 RPC port map entries present in the device, it may result in datapath daemon crash.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1599639The kmd may crash with IPsec tunnel enabled on SRX/vSRX platforms
Product-Group=junos
On SRX/vSRX platforms, if the IPsec VPN tunnel peer information is changed during the SA rekey, the device may leave a stale entry for the original peer entry after the new VPN tunnel is deleted. The kmd may crash and kmd core file is generated if the stale entry is accessed.
1653704The IPSec tunnel via IPv6 might not establish after rebooting SRX devices
Product-Group=junos
On SRX devices, if IPSec is configured with aggressive mode, the IP type of the peer device might differ from the IP address for the IKE (Internet Key Exchange) external-interface. Thus, the VPN tunnel might not come up after rebooting the device. This issue affects only IPv6 VPN sessions.
PR NumberSynopsisCategory: l2 forwarding on non atlas platforms
1664955MAC addresses learned on the RTG interface are not aging out
Product-Group=junos
On Junos EX/NFX/QFX platforms, stale MAC addresses entry not getting removed for RTG (Redundant trunk groups) interfaces.
PR NumberSynopsisCategory: prs for lacp protocol
1635935Traffic loss may be seen on QFX10K due to congestion
Product-Group=junos
During congestion PPMAN(Periodic packet management) run short of resource leading to PDUs (Protocol Data Units) getting failed to be sent. Due to PPMAN queue starvation across TX/RX path, LACP sessions may not get a chance to transmit PDUs which can further lead to peer lacp timeout, aggregated ethernet interface flap and traffic loss.
PR NumberSynopsisCategory: lldp sw on MX platform
1669677LLDP neighborship might fail if the chassis-id format of the LLDP packet is xx:xx:xx:88:8e:xx
Product-Group=junos
On all Junos platforms, Link Layer Discovery Protocol (LLDP) neighborship fails if the chassis-id format of the LLDP packet is xx:xx:xx:88:8e:xx.
PR NumberSynopsisCategory: Multiprotocol Label Switching
1659340LSPs are getting stuck in a down state after deactivating/activate protocol BGP
Product-Group=junos
On all Junos and EVO platforms, when deactivating and activating protocol BGP it impacts the dynamic MVPN P2MP LSPs to stuck in the down state which leads to MVPN traffic loss.
PR NumberSynopsisCategory: MX104 Software - Chassis Daemon
1668983FEB may go down while activating/deactivating GRES configuration
Product-Group=junos
On MX platforms with MIC-MACSEC-20GE, FEB(Forwarding Engine Board) may go down while activating/deactivating GRES(G?raceful Routing Engine Switchover) configuration.
PR NumberSynopsisCategory: This PR category is for tracking only IPv4/ARP/ICMPv4 is
1644616GARP reply doesn't update ARP entry though gratuitous-arp-reply option is configured.
Product-Group=junos
Receiving GARP reply doesn't help update ARP entry though gratuitous-arp-reply option is configured. As a result, traffic loss might be seen depending on the timing.
PR NumberSynopsisCategory: Kernel MPLS / Tag / P2MP Infrastructure
1654798RE kernel crash might be observed in the one-hop-LSP MPLS scenario with RE outbound traffic if 'routing-option resolution preserve-nexthop-hierarchy' is configured globally
Product-Group=junos
On all Junos platforms, if 'routing-option resolution preserve-nexthop-hierarchy' is configured globally, Routing-engine (RE) kernel crash might be observed in the one-hop-LSP Multiprotocol Label Switching (MPLS) scenario with RE outbound traffic.
PR NumberSynopsisCategory: This PR category is for tracking only TCP/UDPtransport layer
1602442On MX and PTX platforms, vmcore on master routing engine might be reported due to mbuf corruption
Product-Group=junos
On MX and PTX platforms, if BGP sessions are activated or deactivated in all the devices, a kernel crash might be seen.
PR NumberSynopsisCategory: Kernel Tunnel Interface Infrastructure
1586169GRE OAM packets are sent through queue 0 with force-control-packets-on-transit-path knob enabled
Product-Group=junos
With force-control-packets-on-transit-path knob enabled, the GRE OAM packets are expectedly sent to queue 3 (network control queue), however, the GRE OAM packets are sent to queue 0.
PR NumberSynopsisCategory: OSPF routing protocol
1659366The memory leak and process rpd crash might be observed when the peer interface flaps continuously in the Segment Routing
Product-Group=junos
On all Junos and Junos OS Evolved platforms configured with Segment Routing, when the peer interface flaps continuously, the memory leak might be observed which might lead to the process rpd crash.
PR NumberSynopsisCategory: Protocol Independant Multicast
1621358Initial multicast register packets may get dropped
Product-Group=junos
On MX platforms, initial multicast register packets may get dropped, this may affect multicast services.
PR NumberSynopsisCategory: vMX Platform Infrastructure related issue tracking
1634908LACP interface might go down when a sub-interface configuration is added and committed to the AE interface
Product-Group=junos
On all MX150 platforms, when an Aggregate Ethernet (AE) interface is configured with LACP and adding a sub-interface configuration under the AE interface causes the LACP down leads to traffic loss.
PR NumberSynopsisCategory: PFE L2
1546572The dcpfe process might crash on QFX10K platforms
Product-Group=junos
On QFX10K platforms the dcpfe might crash if with traffic bring all SIBs offline and then bring them online, it also might happen during the reboot of FPC.
1649637The local-minimum-links feature not working as expected on QFX5100 VC platforms
Product-Group=junos
On the QFX5100 VC(Virtual-Chassis) platform, the AE(Aggregated Ethernet) interface might not go down on a single interface flap in the bundle even though the knob "local-minimum-links" is configured on the device.
1660787CoS might not get applied on VC ports
Product-Group=junosvae
CoS configs are not getting applied on vcp port in QFX5100 VC.
PR NumberSynopsisCategory: All the issues related to PFE MPLS
1666760BGP-LU traffic might be dropped when "CCNH ingress labeled-bgp inet" is configured
Product-Group=junos
On Junos PTX platforms, the native inet packet might not be forwarded correctly when "Chained Composite Next-Hop (CCNH) ingress labeled-bgp inet" is configured. PFE wrongly adds Label 3 to the incoming inet packet and sent the MPLS frame to the edge device where it fails.
PR NumberSynopsisCategory: QFX5100 Virtual Chassis related issues
1667952jnxPowerSupplyFailure and jnxPowerSupplyOK might not be generated for backup FPC
Product-Group=junos
When the power cable is removed/inserted, jnxPowerSupplyFailure and jnxPowerSupplyOK might not be generated on backup FPC.
PR NumberSynopsisCategory: Related to sw defects for K2-RE
1662913The watchdog timeout is encountered and the system reboots after the 'request system halt' command executed
Product-Group=junos
On all platforms with RE-1800 & RE-2000, after the 'request system halt' command is executed, the watchdog timeout is encountered and causes the routing engine (RE) to fail to boot.
PR NumberSynopsisCategory: Interfaces related issues in RPDIssues related to interface
1659102The rpd memory leak might be seen while processing vlan-ccc configuration
Product-Group=junos
On all Junos and Junos Evolved platforms, when deleting/adding the whole interface unit of family vlan-ccc, the rpd will observe a memory leak.
PR NumberSynopsisCategory: KRT Queue issues within RPD stuck queue, retries due to erro
1623170BGP Flowspec might not show counters
Product-Group=junos
On all Junos and Junos Evolved platforms, when installing an IPv6 firewall filter using BGP flowspec, matching traffic counters may show "0" values.
1664527The routing process on the device might crash when the IP address of local interface is changed to the IP address of BGP peer
Product-Group=junos
On all Junos and Junos Evolved platforms, the rpd process might crash when the IP address of local interfaces is changed to BGP peer's IP address. When the IP address is changed, Router NH is created. When this route is leaked to another routing instance, flag is set on the same Router NH instead of creating a new one. This leads to rpd crash. Core files are generated and some traffic impact might be seen.
PR NumberSynopsisCategory: Issue related to mcnh routing infrastructure within RPD
1663568The forwarding plane is not updated properly in scaled MVPN scenario after receiving PIM leave messages
Product-Group=junos
On all Junos and Junos Evolved platforms, when IFLs from non-default routing instances are being added with the OIF scaling of more than 2000 there will be a spillover of IFLNHs into different next hops due to this the outgoing interfaces (OIFs) will not be deleted from multicast next-hop.
PR NumberSynopsisCategory: Non protocols specific issues in RPD policy options, stateme
1666001ACX5448-D policy with install-nexthop, called in forwarding-table will not install next-hops properly with respect to the routing table
Product-Group=junos
Router ACX5448-D failing to install the next hop when a next-hop policy is configured in forwarding-table > show route 172.16.1.2/32 inet.0: 41 destinations, 42 routes (41 active, 0 holddown, 0 hidden) + = Active Route, - = Last Active, * = Both 172.16.1.2/32 *[OSPF/10] 00:16:00, metric 10 > to 100.70.1.101 via xe-0/0/0.0 inet.3: 2 destinations, 4 routes (2 active, 0 holddown, 0 hidden) + = Active Route, - = Last Active, * = Both 172.16.1.2/32 *[RSVP/7/1] 00:15:57, metric 10 > to 100.70.1.101 via xe-0/0/0.0, label-switched-path to_R1 >>>> Installed next-hop [LDP/9] 00:15:57, metric 1 > to 100.70.1.101 via xe-0/0/0.0 ACX5448> ...able destination 172.16.1.2/32 >>>> next-hop is not installing in forwarding table. Routing table: default.inet Internet: Routing table: __juniper_services__.inet Internet: Destination Type RtRef Next hop Type Index NhRef Netif 128.0.0.0/2 intf 0 rslv 529 1 jsrv.1 Routing table: __pfe_private__.inet Internet: Destination Type RtRef Next hop Type Index NhRef Netif default perm 0 dscd 530 2 Routing table: __master.anon__.inet Internet: Destination Type RtRef Next hop Type Index NhRef Netif default perm 0 rjct 545 1
PR NumberSynopsisCategory: Issues related route resolution routing infrastructure
1658277Some L3VPN prefixes are not active because nexthop is not usable
Product-Group=junos
If preserve-nexthop-hierarchy knob was deconfigured and if no-propagate-ttl config within VRF is opposite to global config,some routes can be inactive. Secondary nexthops may not be resolved and active, hence L3VPN routes are not active.
PR NumberSynopsisCategory: RPD route tables, resolver, routing instances, static routes
1657321"--RT--" memory is slowly incrementing in "show task memory detail" output
Product-Group=junos
On all platforms with rib-group configuration or copying route from bgp.l3vpn.0 table to vrf.inet.0 table in case of L3VPN, high scale routes and if any routes are flapped/churned, '--RT--' cookie memory usage might be shown in high value for 'show task memory detail'. This is only a display issue.
1665094Route leaking might happen with auto-export configuration
Product-Group=junos
On all Junos and Junos evolved platforms, if auto-export is configured under VRF, unexpected leaking of the routes could be observed.
PR NumberSynopsisCategory: Scapa specific platform PRs
1614952Line-cards might be unstable due to the continuous growing memory usage of evo-cda-bt app
Product-Group=junos
In PTX platforms running Junos Evolved scenario, if the allocated memory of High-bandwidth Memory (HBM) is not be freed properly by evo-cda-bt after used, the evo-cda-bt might request a new memory block during invoking a periodic or some tasks. As time goes by, the unreleased memory of evo-cda-bt might be accumulated more and more (e.g. 8Mb/per day), the available memory for FPC running will be too low to leak the memory. Finally, the FPC might be unstable.
PR NumberSynopsisCategory: SW PRs for SCBE3 chassisd
1667226The hyper-mode might be set incorrectly after power cycle on MX platforms
Product-Group=junos
The hyper-mode can be set incorrectly after power cycle on MX platforms when either BBE and/or MX VC is configured and hyper-mode is not configured.
PR NumberSynopsisCategory: Issues related to Junos SNMP Infrastructure (snmpd, mib2d)
1666548The "snmpd" process might crash if SNMP timeout happens
Product-Group=junos
On all Junos and EVO platforms, the "snmpd" process might crash, if there is no response for the SNMP requests and a timeout happens.
PR NumberSynopsisCategory: Generic platform and infra issues for MS-MIC and MS-MPC(XLP)
1668152periodic event generation doesn't work after RE reboot
Product-Group=junos
Service-oid.slax script is hooked to ?Starting of initial processes complete? system message from jlaunchd for reboot scenario using event policy infra. The exact system message as follow? Jun 8 23:37:50.477 jtac-mx480-r2040-re1 jlaunchd[11487]: Starting of initial processes complete However, on the recent releases we observed that this message coming from kernel intermittently and thus event policy fails to detect it Message from kernel looks as follows Jun 8 23:37:54.000 jtac-mx480-r2040-re0 kernel: jlaunchd 11515 - - Starting of initial processes complete Therefore, can observe periodic event generation stop working after RE reboot.
PR NumberSynopsisCategory: security-intelligence feature on SRX
1638923Kernel panic might be seen during boot
Product-Group=junos
On Junos platforms kernel panic might be seen during the boot sequence.
PR NumberSynopsisCategory: Trinity LU, IX, QX, MQ chip drivers, ucode & related SW
1651407CCL-DT-BNG: show interface and monitoring interface (ifd level) counters are tripled.
Product-Group=junos
In a subscriber management scenario requiring four subscriber accurate accounting statistics per packet, three stats are handled correctly while the fourth one - ifd stat - is not handled correctly due to this PR. The net effect is only the ifd byte statistic may not be accurate while the ifd packet count is still accurate. Also there is no service or traffic impact due to this issue.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1647214DHCP Subscriber traffic might get dropped due to the rpf-check filter
Product-Group=junos
On all Junos platforms running BroadBand Edge(BBE) subscribers, when the rpf-check CLI knob is present in the configuration but the Reverse Path Forwarding (RPF) feature is not getting applied to certain subscribers which leads to DHCP subscriber traffic drop.
PR NumberSynopsisCategory: trinity pfe qos software
1591905The subscribers might not come online after interface flaps on MX platforms
Product-Group=junos
On MX platforms in BNG scenario, all subscribers under the interface of MPC3D 16x10GE/MPC1/MPC2 line cards might not be able to login after interface flaps.
PR NumberSynopsisCategory: trinity pfe l3 forwarding issues
1641323Out of order packets might be seen in multicast streams with MVPN extranet scenario
Product-Group=junos
Out of order packets might be seen in multicast streams with MVPN extranet scenario, if multicast source route is missing in the receiver VRF.
1656499GRE-in-GRE encapsulated traffic might be dropped when the recursion-control bit is set to non-zero, which does not comply with RFC standard
Product-Group=junos
On all Junos MX platforms, the Generic Routing Encapsulation (GRE) packet might be dropped in a GRE-in-GRE scenario if the recursion-control bit is set to non-zero. This problem is not seen with single GRE encapsulation.
1662950TCP MSS value might not get reflected to packets
Product-Group=junos
On MX platforms with TCP MSS (TCP maximum segment size)configured, mss value might not get stamped/configured to TCP packets when transiting through the device.
PR NumberSynopsisCategory: trinity pfe multicast software
1655363Multicast packet drop causes pixelization
Product-Group=junos
On all MPC1/MPC2NG/MPC3NG/MPC7/MPC8/MPC9/MPC10/MPC11/LC9600/MX304 line cards, the multicast traffic drop could be observed. Only a few mcast packets get dropped, hence pixelization is seen on the receiver. The packet for the static receiver on the router passes through the policer on the loopback filter. Only those packets that pass through are looked into by the firewall loopback filter.
PR NumberSynopsisCategory: Issues related to Junos Automation, Commit/Op/Event and SLAX
1604622File download using "request system download" might fail
Product-Group=junos
On a EX4400 device, any files scheduled for download using the cli command "request system download" might fail due to error. The files can be downloaded using normal ftp/scp commands on the device.
PR NumberSynopsisCategory: Issues related to mgd, DAX API, DDL/ODL infrastructure, Juno
1608718In an SRX cluster with VPN configuration, primary node in cluster may generate kmd core files in a loop when a commit fails with "lock can not be taken on other node" followed by another commit
Product-Group=junos
When a commit is failed, "/var/etc/vpn_tunnel.id+" and other ffp(foreign file propagation) files are not getting cleaned up on srx cluster. In next commit, these stale ffp files are activated for use, it is resulting in discrepancy and resulting in assert failure in applications/KMD daemons. The problem moves to the secondary node if the failover is executed.
PR NumberSynopsisCategory: Virtual Private LAN Services
1655858The Pseudo Wires might go down in VPLS scenario
Product-Group=junos
On all Junos/Junos Evolved platforms with VPLS (virtual private LAN service) deployed, deactivating and activating the neighbour under the default mesh-group might lead Pseudo Wires(PW) to go down. This happens when there is a change in default mesh-group and that might not be updating the PW status. This can be recovered by deactivating and activating the complete routing instance under the mesh-group.
PR NumberSynopsisCategory: usf nat related issues
1610977Traffic might not be processed when mams-members are replaced in the AMS bundle
Product-Group=junos
On all MX platforms with SPC3 card having MAMs interface configured in AMS bundle, traffic/data packet loss might be seen. Packets might be seen discarded as "NAT allocation failures".
1659284Multiple stale EIM mappings observed on Junos MX platforms due to the aging timer getting stuck
Product-Group=junos
On Junos MX platforms, NAT (Network Address Translation) allocation failures are seen in case of EIM (Endpoint Independent Mapping) where the mappings are leaked and become stale, that is, they do not age out. The aging timer gets stuck leading to a failed NAT session.
 
 

19.4R3-S9 - List of Known issues

PR NumberSynopsisCategory: Mojito PFE
1675977The fxpc process crash might be observed on EX4300 and EX4300-VC platforms
Product-Group=junos
On EX4300 platforms, if there are mac-move events, the fxpc (Packet Forwarding Engine manager) crash might be observed due to race conditions.
PR NumberSynopsisCategory: Category for all the Sazerac & Macallan PFE PRs
1633883The EX2300 may unexpectedly drop VOIP VLAN traffic after reboot
Product-Group=junos
On the EX2300 platform, the traffic drop may be observed on VOIP VLAN after the device reboot. Voice VLAN on EX2300 may not forward traffic correctly out of the interface when the device is either power-cycled / halted / power off or power on, and may not communicate with the default gateway.
PR NumberSynopsisCategory: PRs for Subscriber Management Statistics daemon & libraries
1676049Minor memory leak in 'bbe-statsd' daemon may be seen when subscriber-management is enabled on MX platforms
Product-Group=junos
On MX platforms, a minor memory leak may be seen over time for transient subscriber sessions which last for around 30 seconds or less. The issue is reproducible consistently and may result in 'bbe-statsd' daemon crash over time.
PR NumberSynopsisCategory: Bi Directional Forwarding Detection
1675921Micro BFD session state in RE remain UP even peer side session is down.
Product-Group=junos
Any platforms with Micro BFD configured on member links of the LAG/ae interface, BFD Session state in RE remains as UP always even though PEER device has ceased.
PR NumberSynopsisCategory: Manageability SW defect for Dvaita NPI (Node Virtualization)
1583324JDM server creation might fail on junos node slicing setup in in-chassis mode
Product-Group=junos
On MX platforms the JDM (Juniper Device Manager) server could not be created in in-chassis mode of junos node slicing, which results in mgd process crash and affects GNF's (Guest Network Function) provisioning.
PR NumberSynopsisCategory: EVPN control plane issues
1659786The process rpd might crash when protocol EVPN is deactivated
Product-Group=junos
On all Junos and Junos OS Evolved platforms, with multiple activating/deactivating Ethernet Virtual Private Network (EVPN) or deactivating the Virtual Routing and Forwarding (VRF) instance with protocols EVPN for type 5 route, the process rpd might crash.
PR NumberSynopsisCategory: PRs for Lagavulin PFE tracking
1603015On EX4400 dot1x authentication may not work on EVPN/xlan enabled endpoints.
Product-Group=junos
On EX4400 dot1x authentication may not work on EVPN/xlan enabled endpoints. The issue is due to EAPOL packets received on VxLAN ports are not processed in hostpath.
PR NumberSynopsisCategory: jl2tpd daemon
1667950VMcore or RE crash might be triggered due to the memory corruption when the FPC is restarted for LNS subscribers
Product-Group=junos
On all MX platforms, when Flexible PIC Concentrators (FPCs) restart for L2TP network server (LNS) subscribers stacked over aggregated service interface (asi) and LNS subscribers belong to more than one routing instance causes the VMcore or Routing Engine (RE) crash and brings down all the traffic.
PR NumberSynopsisCategory: IPSEC/IKE VPN
1673391High Control Plane CPU utilisation while the kmd process is stuck after the core file
Product-Group=junos
On all SRX platforms, during key management (kmd) core file, with VPN/Internet Key Exchange (IKE) implemented and a high number of file descriptors open, the kmd process will reach above 80% CPU utilisation and stay for a long period of time if the kmd process is stuck after the core file is generated.
PR NumberSynopsisCategory: l2 forwarding on non atlas platforms
1612738The process l2ald may crash during routing-instance configuration change
Product-Group=junos
If configuration change in EVPN routing instance may cause existing dynamic mesh group readded to kernel. This cause l2ald core. But this core doesn't affect service and l2ald will return to correct state after core.
PR NumberSynopsisCategory: Mobile Edge AAA related issues
1654947In a subscriber scenario, AAA module of "mobiled" process may cause memory leak on the standby routing-engine
Product-Group=junos
On all Junos platforms where subscriber management is enabled, standby RE may see slow memory leak due to AAA component of "mobiled". The leak is about 24B/sec.
PR NumberSynopsisCategory: Kernel Multicast Infrastructure
1653920Traffic blackhole might be seen due to next-hop install failure on Junos PTX platforms
Product-Group=junos
On Junos PTX platforms there might be a traffic blackhole which happens because of next-hop installation failure for multicast RSVP(Resource Reservation Protocol) P2MP(Point to Multipoint) traffic. This issue might only be encountered in a scaled RSVP P2MP environment after a network event which might cause reconvergence.
PR NumberSynopsisCategory: All issues related to L3 data-plane/forwarding
1629178Junos OS: EX4600 Series and QFX5000 Series: Receipt of specific traffic will lead to an fxpc process crash followed by an FPC reboot (CVE-2022-22203)
Product-Group=junos
An Incorrect Comparison vulnerability in PFE of Juniper Networks Junos OS allows an adjacent unauthenticated attacker to cause a Denial of Service (DoS). Please refer to https://kb.juniper.net/JSA69707 [juniper.net] for more information.
PR NumberSynopsisCategory: PRs for PFE EVPN / VxLAN related issues on QFX5K
1645929An interface might be detached from LACP when configuring VLAN tagging in the EVPN-VXLAN scenario on Junos QFX5K platforms
Product-Group=junos
On Junos QFX5K platforms, the LACP packet might get intercepted and the interface detached from LACP when configuring VLAN tagging in the EVPN-VXLAN scenario.
PR NumberSynopsisCategory: Interfaces related issues in RPDIssues related to interface
1639134The dynamic tunnel might flap every 15 mins with a non-forwarding route
Product-Group=junos
On all Junos and Junos Evolved platforms, the dynamic tunnel might flap every 15 mins when a non-forwarding route is resolving over the dynamic tunnel. The non-forward route resolution on a dynamic tunnel route might not be successful. As the route resolution is having impact, traffic drop might be seen in peer nodes.
PR NumberSynopsisCategory: KRT Queue issues within RPD stuck queue, retries due to erro
1388119During link flap, kernel veto messages are seen and traffic is being blackholed
Product-Group=junos
In JUNOS 16.1/later releases, when the quick interface "down/up" happens, IGP and BGP protocols perform RIB route-change, in some sceanrios we may observe rt_pfe_veto messages in syslog, due to slow PFE consumption, kernel will throttle RPD by sending ENOBUFS. In order to avoid this scenario we can configure in JUNOS the following values to the Kernel Routing Table IO: set routing-options krt-io-options work-queue-length high-threshold 250 set routing-options krt-io-options work-queue-length low-threshold 200 set routing-options krt-io-options tx-bulk-count 10 Important Notes: The above commands require RPD restart to take effect. When the "interface down" happens, IGP and BGP protocols perform RIB route-change. The IGP change is placed into a high priority queue and the exterior route change is placed into a low priority queue. For 64-bit systems, RPD workqueue size is 10000 and bulk count is 30. As a result, the head of line blocking for the IGP route change could potentially be up to 300000 rtsock requests, which causes the delay in FIB convergence for that particular prefix when the interface comes up immediately after interface down.
PR NumberSynopsisCategory: Reserved for Internal use by RPD Infra team only.
1419662Protocol flap and other unexpected behavior during MX104 routing-engine GRES/NSR mastership switchover
Product-Group=junos
MX104 is known to have slow routing-engine I/O. Extended scheduler slip due to long configuration/route processing during switchover. Protocol flap was a result of scheduler slip. There's no guarantee in protocol stability during rpd scheduler slip. After switchover, protocols reconfig is done again in a tight loop and no other rpd infra task run during that time. Scheduler slip is reported for that duration of ~100 seconds. This RPD slip gets reported when rpd's main loop do not get a chance to run. And in this case it was due to reconfig being done in tight loop. Kernel should be scheduling other daemons as usual. From rpd infra side this a day-1 behaviour. The behavior cannot be resolved by a PR. This PR will be closed as product limitation with high risk of fix. This requires extensive RLI work.
PR NumberSynopsisCategory: Resource Reservation Protocol
1593959ISIS BFD sessions may take a long time to recover when the interface flaps
Product-Group=junos
When RSVP link-protection bypass LSPs active after the primary link goes down and comes back up. The BFD session over the interface stays down until all LSPs using the bypass LSPs come back up. This happens because RSVP installs a /32 route pointing to the bypass tunnel which is required to signal backup LSPs. This route is removed when all LSPs stop using bypass after the link comes back up. This is day 1 RSVP behavior.
1657872Memory utilization keeps incrementing due to the path error message
Product-Group=junos
On all Junos and Junos Evolved platforms, when a no-cspf Label Switched Path (LSP) with strict Explicit Route Object (ERO) is configured and the egress device is disconnected, a high rate of Path Error (PathErr) messages are observed which is leading to high memory utilization and triggering the chassisd crash that causes the device to be out of control, either it can not be accessible via console/ssh or it will not trigger Routing Engine (RE) switchover as well if it is dual-RE. So this would cause an outage.
PR NumberSynopsisCategory: This would be category for IPSEC functionality on M/MX/T ser
1674585The 'kmd' process may crash due to SA re-negotiation failure during IKE phase-1
Product-Group=junos
On platforms running Junos 16.2 onwards releases, if for some reason IKE (Internet Key Exchange) phase-1 SA (Security Association) re-keying fails, 'kmd' process may crash and the IPSec (Internet Protocol Security) tunnels may also get torn down. Most of the time, the reason is that the initiator changes its offerings after the initial successful key exchange.
PR NumberSynopsisCategory: issues related to snorkel card
1192914Changing MPC firmware to help better troubleshooting and recover from firmware crashes
Product-Group=junos
On MX Series routers with MPC3/MPC4/MPC5/MPC6 (may also affect EX92xx, e.g. with an EX9200-32XS, SRX5000 platforms), the VSC8248 firmware on the MPC crashes occasionally. This PR enhances the existing VSC8248 PHY firmware crash detection and recovery, helping recover from a few corner cases where the existing Junos OS workaround does not work.
PR NumberSynopsisCategory: Remote Access VPN issues on SRX
1571326HTTPS connection might timeout when remote access VPN connection with Juniper Secure connect fails
Product-Group=junos
On all SRX-series devices with tcp-encap profile (with ssl-t profile i.e pfv2) attached to ike-gw, when large number of sessions (say above 4lacs) are processed by flow, remote access VPN connection fails. This leads to HTTPS connection timeout.
PR NumberSynopsisCategory: ZT/YT pfe firewall software
1627986FPC might restart with syslog filter action configured
Product-Group=junos
On EVO-based PTX platforms and all MX series platforms with MPC10+, configuring syslog as a filter action may cause the FPC to restart.
PR NumberSynopsisCategory: Issues related to broadband edge apps (PPP, DHCP) on Trio ch
1570676When traffic towards client gets fragmented PPP/LNS Radius downlink accounting inaccurate with peer LCP negotiated MRU.
Product-Group=junos
When traffic towards client gets fragmented PPP/LNS Radius downlink accounting inaccurate. As of now this is unsupported.
PR NumberSynopsisCategory: Issues related to mgd, DAX API, DDL/ODL infrastructure, Juno
1673176"gethostbyname: Host name lookup failure" is displayed during commit
Product-Group=junos
On all SRX series platform with J-web enabled, "gethostbyname: Host name lookup failure" is displayed during commit
PR NumberSynopsisCategory: Vale fabric related issues.
161594290% traffic got dropped when the number of Switch Interface Board (SIB) plane is reduced from 4 to 3 on PTX10008 and PTX10016
Product-Group=junos
On PTX10008 and PTX10016 routers, when the number of Switch Interface Board (SIB) planes is reduced from 4 to 3, traffic might drop by 90%.
 

Modification History

First publication 2022-08-29